Forum Moderators: open

Message Too Old, No Replies

Mozilla takes a turn slapping Symantec's certification SNAFU

         

tangor

8:48 pm on May 3, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Mozilla has weighed in to the ongoing Symantec-Google certificate spat, telling Symantec it should follow the Alphabet subsidiary's advice on how to restore trust in its certificates.

Readers will recall that Symantec has repeatedly issued certs that didn't ring true with browser-makers and at the end of April 2017 Google started a countdown, the conclusion of which would see its Chrome browser warn users if it encountered Symantec certs.

Symantec offered up a remediation plan, mostly based on putting auditors through the joint. But it looks like that's not sufficient for Mozilla.

[theregister.co.uk...]

Many of us use FF, so this is of some interest....

keyplyr

3:49 am on Jun 1, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Google made the initial announcement on or about March 24, 2017 that Chrome would immediately stop support of Symantec certs, but I haven't seen anything in the Chrome browser. Maybe Symantec certs are just showing the same non-secure warning as a site without a cert.

At that time, Symantec had issued over 30,000 certs so with the amount of surfing I do each day, I should have come across at least one of these.

I stopped using FF about a year ago because of the bloat, but occasionally check my own work with it... as I do with Safari & Edge.

tangor

8:38 am on Jun 1, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



G's report was based on 127 certs identified, the 30,000 is what Symantec issues.

[itpro.co.uk...]

Scroll down or page (it's a 3 pager article) for skinny on that.

That said... same article regards comparison with FF Chrome, Edge and IE. Interesting stats with (near end of article) FF as the win but all kinds of love for Chrome. Edge gets high marks and IE is last, where it should be (though it was the BEST at javascript, and that means ALL of the contestants).

We use the tools we like for personal stuff. We also use all the other tools to see how things work for others in the real world.

For me, Chrome exists on only one machine and everything I can turn off (ie, reporting home, mining my data) is turned off. What Chrome STILL SENDS to the g plex is amazing and I, to this day, marvel that folks just give it up. :)

Re: Symantec, there's blood in the water and sharks circling. I suspect there's some back-stabbing going on as they have about 1/3 of the cert market and others want to steal their biz, or shut their cert biz down.